// 3 CRITICAL · 2 ZERO-DAY · 4 CVE · 3 EXPLOIT · 1 ADVISORY IN THE LAST 24H
CYBERSECZERO-DAY

June 2026 Patch Tuesday: Microsoft's Largest Ever, With Three Publicly Disclosed Zero-Days

Microsoft fixed nearly 200 vulnerabilities in the June 2026 Patch Tuesday, the most voluminous monthly cycle in the company's history.…

Aug 07, 2026views - 1.1k

CYBERSECEXPLOIT

Cisco Confirms Active Exploitation of Hard-Coded Credentials in Secure Firewall Management Center

Cisco has confirmed active in-the-wild exploitation of CVE-2026-20316, a static credential vulnerability in Secure Firewall Management…

Aug 07, 2026views - 1.2k

CYBERSEC

Swiss Federal SharePoint Breach Compromises 200 Accounts

The Federal Office for Information Technology and Telecommunication (BIT/FOITT) confirms exploitation of already-patched SharePoint fl…

Aug 07, 2026views - 1.1k

CYBERSECCRITICAL

VMware vCenter Hit by Two Critical Flaws With No Workarounds: The Remediation Plan

Broadcom has patched two critical vulnerabilities in vCenter Server, both rated CVSS 9.8. No workarounds exist for CVE-2026-59309 and…

Aug 06, 2026views - 1.2k

VULNZERO-DAY

Samsung Patches Android Zero-Day Discovered by Meta: The Invisible Chain of Responsibility

Samsung has patched CVE-2025-21043, an out-of-bounds write in libimagecodec.quram.so enabling remote code execution. The flaw was repo…

Aug 06, 2026views - 1.2k

VULNCRITICAL

ZDI-26-520: Pre-auth RCE in Phoenix Contact EV Charging Controller

A path-validation flaw in the firmware-update endpoint of the Phoenix Contact CHARX SEC-3150 EV charging controller allows unauthentic…

Aug 06, 2026views - 1.2k

cveCVE

CISA Orders 3-Day Patch Deadline for CVE-2026-18577 in N-able N-central

CISA added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog with a three-day patching deadline for federal agencies. The…

Aug 05, 2026views - 1.3k

CYBERSEC

ChainDrop: The npm Worm That Compromised 444 Packages in Under Four Hours

Analysis of the August 4, 2026 ChainDrop attack: a self-replicating npm worm that abused OIDC Trusted Publishing with valid SLSA prove…

Aug 05, 2026views - 1.4k

VULNCRITICAL

Apple Patches ImageIO RCE: Numeric Truncation Fixed in macOS Tahoe 26.6

CVE-2026-43780 in Apple's ImageIO framework allowed remote code execution via malicious textures. The fix is available today across ei…

Aug 05, 2026views - 1.3k

CYBERSEC

Bitdefender Shredder Privilege Escalation to SYSTEM: Update Immediately to 27.0.58.315

ZDI-26-448 exploits Bitdefender's File Shredder to escalate local privileges to SYSTEM. CVE-2026-6851 carries a CVSS 4.0 score of 7.0;…

Aug 05, 2026views - 1.2k

CYBERSEC

Trend Micro Cleaner One Pro: File Cleanup Turns Into a SYSTEM-Level Attack

A vulnerability in the Junk Files Cleanup component of Trend Micro Cleaner One Pro allows a local attacker to delete arbitrary files w…

Aug 05, 2026views - 1.2k

CYBERSECCRITICAL

WatchGuard FireWare OS: Directory Traversal in sigd Service Opens Path to Code Execution

A directory traversal vulnerability in the sigd service of WatchGuard FireWare OS allows an authenticated remote attacker to create ar…

Aug 05, 2026views - 1.3k